Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2018-16660
Disclosure Date: April 25, 2019 (last updated November 27, 2024)
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation.
0
Attacker Value
Unknown
CVE-2018-5403
Disclosure Date: January 10, 2019 (last updated November 27, 2024)
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.
0
Attacker Value
Unknown
CVE-2018-5413
Disclosure Date: January 10, 2019 (last updated November 27, 2024)
Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.
0
Attacker Value
Unknown
CVE-2018-19646
Disclosure Date: November 28, 2018 (last updated November 27, 2024)
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.
0